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AMENDMENTS TO THE CLAIMS 



Please amend the claims as indicated hereafter. 



(Previously Presented) A method of delivering a digital document to an intended 
recipient at a printout station, the method comprising: 

receiving and securely retaining a transmitted document at the printout station; 
receiving an independently verifiable data record of the intended recipient at the 
printout station; 

obtaining a fust token of the intended recipient; 

requesting proof of the intended recipient's identity at the printout station using 
ta in the independently verifiable data record of the intended recipient; and 

releasing the document when the intended recipient has proved their identity by 
s of a second token that is uniquely related to the first token, wherein the retaining step 
i printing out the document as received and placing it in a locked compartment 
the releasing step comprises a controller unlocking the compartment where the 
printed copy of the document is stored. 



cc mprises 



an i 



(Original) A method according to Claim 1, wherein the transmitted document is a 
document and the printout station comprises a fax machine. 



3-C . (Canceled) 



(Original) A method according to Claim 1, wherein the requesting step comprises 
supply of data encoded with the second token which can be decoded with the 
token. 



req lesting 



firs 



(Original) A method according to Claim 1, wherein the releasing step is carried 
when the intended recipient has presented a portable data carrier holding the second 
to the printout station and has transferred data to prove their identity. 
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(Original) A method according to Claim 8, wherein the releasing step further 
ccmprises the intended recipient entering a verifiable security identifier into the printout 
st ition to establish that they are the legitimate owner of the portable data carrier 

1< >. (Original) A method according to Claim 8, wherein the portable data carrier is a 
sr lart card and the printout station comprises a smart card reader. 
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(Previously Presented) A method according to Claim 1, wherein the obtaining 
sp comprises extracting the first token transmitted with the data record. 

(Original) A method according to Claim 11, wherein the intended recipient's 
lependently verifiable data record is provided as an intended recipient's digital 
ce rtificate. 

13 , (Original) A method according to Claim 1, further comprising carrying out an on- 
lir e check of the validity of the intended recipient's independently verifiable data record. 

14 (Original) A method according to Claim 1, further comprising instructing a third 
pa ty to cany out an on-line check of the validity of the intended recipients independently 
ve ifiable data record. 

15 (Original) A method according to Claim 13, wherein the releasing step furtaer 
co] nprises only releasing the document if the validity of the independently verifiable data 
record has been confirmed as a result of the check. 

16J (Original) A method according to Claim 14, wherein the releasing step further 
cor iprises only releasing the document if the validity of the independently verifiable data 
record has been confirmed as a result of the check. 

17. (Previously Presented) A method according to Claim 1, wherein the first and 
sec md tokens comprise public and private encryption/decryption keys, respectively, of 
the intended recipient. 



3 
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2 1 . (Previously Presented) A method of delivering a digital document to a group of 
intended recipients at a printout station, the method comprising: 

obtaining a first token of each intended recipient that belong to the group of 
intended recipients; 

encoding the digital document with a session key using a symmetric cryptographic 
encryption algorithm, and encrypting the session key with the first token using an 
encryption algorithm that is more computationally intensive than the symmetric 
: jytographic encryption algorithm; 

receiving and securely retaining the digital document, the encrypted session key 
an independently verifiable data record of each intended recipient at a printout 
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requesting proof of each intended recipient's identity at the printout station using 
in the independently verifiable data record of the intended recipient; 

receiving proof of each intended recipient's identity in the form of a second token 
quely related to the first token; and 

decrypting the encrypted session key with the second token, decoding the digital 

with the decrypted session key, and releasing the document, wherein: 
the receiving step comprises receiving a plurality of transmitted independently 

data records of the intended recipients at the printout station; 
the obtaining step comprises obtaining the first tokens of each of the intended 

in the group of intended recipients; 
the requesting step comprises requesting proof of each of the intended recipients' 
at the printout station using data in the independently verifiable data records of 
intended recipients; and 

the processing step comprises processing each of the intended recipients' response 
request and releasing the document when all of the intended recipients have proved 
identity by use of respective second tokens that are each uniquely related to 
ective ones of the first tokens. 



do :ument ' 
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ide itities 
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(Original) A method according to Claim 21, wherein the transmitted document is 
document and the printout station comprises a fax machine. 
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(Original) A method according to Claim 21, wherein the retaining step comprises 
Coring the received document in memory without printing out a copy of it on receipt. 

2 5. (Original) A method according to Claim 25, wherein the releasing step comprises 
p rinting out a copy of it. 

27. (Original) A method according to Claim 21, wherein the requesting step 
a )mprises requesting supply of data encoded with the second token which can be decoded 
wjith the first token. 

(Previously Presented) A method according to Claim 21 wherein the releasing 
stsp is carried out when each intended recipient has presented a portable data carrier 
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3-24. (Canceled) 



lding the second token to the printout station and has transferred data to prove their 



id sntity. 
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(Previously Presented) A method according to Claim 28, wherein the releasing 
stc p further comprises each intended recipient entering a verifiable security identifier into 
th.: printout station to establish that they are the legitimate owner of the portable data 



cai rier. 



30 



(Original) A method according to Claim 28, wherein the portable data 
smbrt card and the printout station comprises a smart card reader. 



earner ts a 



(Original) A method according to Claim 21, wherein the obtaining step comprises 
extracting the first token transmitted with the document and the data record. 



32. 

recibient 



(Previously Presented) A method according to Claim 31, wherein each intended 
;'s independently verifiable data record is provided as an intended recipient's 



digi tal certificate 
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(Previously Presented) A method according to Claim 21, farther comprising 
darrying out an on-line check of the validity of each intended recipient's independently 
^ erifiable data record. 

34. (Previously Presented) A method according to Claim 21, further comprising 
instructing a third party to carry out an on-line check of the validity of each intended 
r scipient's independently verifiable data record. 

(Previously Presented) A method of according to Claim 33, wherein the releasing 
sjep further comprises only releasing the document if the validity of each independently 
v arifiable data record has been confirmed as a result of the check. 



(Previously Presented) A method according to Claim 34, wherein the releasing 
?p further comprises only releasing the document if the validity of each independently 
e data record has been confirmed as a result of the check. 
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(Previously Presented) A method according to Claim 21, wherein the first and 
*>nd tokens comprise private and public encryption/decryption keys of the intended 



re< ipient 



(Canceled) 



(Previously Presented) A method according to Claim 21, wherein the transmitted 
or a session encryption/decryption key of the transmitted document has been 
encrypted with each of the first tokens of the intended recipients in a given 
and the processing step comprises sequentially decrypting the transmitted document 
session encryption/decryption key with each of the second tokens of the intended 
recipients in the reverse of the given sequential order. 
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<■ 0. (Previously Presented) A method of delivering a digital document to intended 
i scipients at a printout station, the method comprising: 

receiving and securely retaining a transmitted document at the printout station; 
receiving a plurality of independently verifiable data records of the intended 
recipients at the printout station; 

obtaining first tokens of each of the intended recipients; 

requesting proof of each of the intended recipient's identities at the printout station 
u|smg data in the independently verifiable data records of the intended recipients; and 

processing each of the intended recipients' responses to the request for proof and 
rjleasmg the document when all of the intended recipients have proved their identity by 
;e of respective record tokens that are each uniquely related to respective-ones of the 
:st tokens. 



42. 



(Previously Presented) A device for delivering a digital document to an intended 
re ;ipient, the device comprising: 

a communications module for receiving an electronic version of the transmitted 
ddcument over a communications network, receiving an independently verifiable data 
record of the intended recipient, and receiving a first token of the intended recipient; 

a store for securely retaining the transmitted document, the transmitted 
in|ependently verifiable data record and the first token; 

an mstructioo module for requesting proof of the intended recipient's identity 
usfig data provided in the intended recipient's data record; 

a controller for releasing the document when the intended recipient has proved 
th^r identity by use of a second token that is uniquely related to the first token; 

a portable data carrier reader for receiving information from a portable data carrier 
stojing the intended recipient's second token; and 

one or more lockable compartments and the device is arranged to print out the 
doqWent as received and place it in one of the compartments, wherein the controller is 
am aged to release the locked compartment containing the document, once the intended 
reci pient has proved their identity. 



fax nachine, 



(Original) A device according to Claim 41, wherein the device comprises a 
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3. (Previously Presented) A device according to Claim 41, wherein the first and 
econd tokens comprise public and private encryption/decryption keys of the intended 
r 3cipient 



A 4-47. (Canceled) 



48 



in 



us 



(Original) A device according to Claim 41, wherein the controller is arranged to 
rjjease the received document when the intended recipient has entered a verifiable 
s scurity identifier into the printout station to establish that they are the legitimate owner of 
tl e portable data carrier, 

4 ). (Previously Presented) A device for delivering a digital document to an intended 
xt cipient, the device comprising: 

a communications module for receiving an electronic version of the transmitted 
djcument over a communications network, receiving an independently verifiable data 
rejjord of the intended recipient, and receiving a first token of the intended recipient; 

a store for securely retaining the transmitted document, the transmitted 
lependently verifiable data record and the first token; 

an instruction module for requesting proof of the intended recipient's identity 
ng data provided in the intended recipient's data record; 

a controller for releasing the document when the intended recipient has proved 
thjir identity by use of a second token that is uniquely related to the first token; and 

one or more lockable compartments and the device is arranged to print out the 
document as received and place it in one of the compartments, wherein the controller is 
arr inged to release the locked compartment containing the document, once the intended 
pient has proved their identity. 



rec 
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mac hine 



(Original) A device according to Claim 49, wherein the device comprises a fax 

ft 
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(Previously Presented) A device according to Claim 49, wherein the first and 
second tokens comprise public and private encryption/decryption keys of the intended 
i ecipient. 

i 3. (Original) A device according to Claim 49, wherein the controller is arranged to 
r jlease the received document when the intended recipient has entered a verifiable 
s scurity identifier into the printout station to establish that they are the legitimate owner of 
portable data carrier. 
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(Previously Presented) A method of delivering a digital document from a first 
ation via a communications network to an intended recipient at a second station, the 
ethod comprising: 

obtaining details of the intended recipient, including an independently verifiable 
record of the intended recipient at the first station; 

determining prior to transmission of the document whether the second station is 
which is arranged to stop a transmitted document from being released until the 
recipient has proved their identity, wherein the first station is configured to 
eroatively transmit the document as a non-encrypted transmission when the second 
is determined to not be capable of stopping a transmitted document from being 
eased until the intended recipient has proved their identity; 

transmitting the document to the second station prior to receiving proof of an 
recipient's identity, 

transmitting the independently verifiable data record of the intended recipien t to 
second station; 

receiving and securely retaining the transmitted document at the second" station 
to receiving proof of the intended recipient's identity and receiving the data record at 
second station; 

obtaining a first identifying token of an intended recipient at the second station; 
requesting proof of the intended recipient's identity at the second station using the 

" independently verifiable data record; and 
releasing the document to the intended recipient when the intended recipient has 
their identity using a second identifying token related to the first identifying token. 
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(Original) A method according to Claim 54, further comprising obtaining details 
of the intended recipient including the independently verifiable data record prior to 
1 ransmitting the document. 

6. (Original) A method according to Claim 55, wherein the step of obtaining details 
omprises obtaining the independently verifiable data record from a central database 
s toring many possible intended recipients' details. 

(Previously Presented) A method according to Claim 54, wherein the intended 
recipient's independently verifiable data record is provided in an intended recipient's 
c igital certificate. 

5 3. (Previously Presented). A method according to Claim 54, further comprising 
e icoding the document prior to transmitting it to the second station and decoding the 
n ceived document once the intended recipient has proved their identity. 

5! >. (Original) A method according to Claim 58, wherein the encoding/decoding steps 
c< mprise using enveloping encryption/decryption techniques. 

6( ^62. (Canceled) 

62 . (Currently Amended) A method according to Claim 54 49, wherein the intended 
re Rent's independently verifiable data record is provided in an intended recipient's digital 
ce tificate. 

64 -65. (Canceled) 
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